1 Emerging Security Challenges for Ubiquitous Devices
5
Note that in the second case there might be no security alert. For instance, distance
bounding protocols explicitly admit failures.
While the most effective methods of the types mentioned in point 1 require
asymmetric cryptography (see, e.g., [590]), there are possibilities to create narrow
covert channels even if a random string is processed with, say, a hash function.
Assume for instance that the device chooses r at random, while Hash(r) is available
to the adversary. Assume that a malicious device executing the protocol intends to
leak bits of a string μ of length 2 l . Assume also that it has a secret key k shared
with the adversary, who is observing the communication channel. Instead of just
choosing r at random, computing Hash(r), and presenting it, the following steps are
executed:
1. choose r at random, s := Hash(r), z := Hash(s, k),
2. parse z as a||b|| . . ., where a consists of l bits and b consists of m bits,
3. goto 1, if the m-bit substring of μ starting at position a is different from b,
4. output s.
Of course, this is a narrow channel, as m must be small enough so that an
appropriate r can be found in a reasonable time—in practice we are talking about
a few bits per protocol execution. Note that this procedure works for any hash
function. It works also if the loop may be executed only a limited number of times
and, during the last loop execution, steps 2 and 3 are omitted. Unfortunately, if a
device is delivered as a black-box, then the possibilities to inspect what the device
is doing are severely limited. There are only a few exceptions (see, e.g., [94]).
1.2.2 Active Watchdog Concept
The general idea is that a device is controlled by its dedicated watchdog coming
from a source independent from the device manufacturer and the device provider.
The watchdog should detect malicious operation or make it ineffective, given that
no access to the internal operation of the device controlled is granted. A watchdog
is an active device, modeled as follows:
• it controls the whole communication between the device and the external world,
• it can delete and change all messages,
• it may challenge the device during extra interactions executed by them.
The idea of separating the tasks between two independent devices is an old
concept [136]. The same concerns supervising computation correctness by an
external unit [97]. Nevertheless, it has attracted more attention in the post-Snowden
era, being used, among others, in a solution guarding against subversion attacks on
cryptographic devices—see the paper [31] and an extension [510].
5
Note that in the second case there might be no security alert. For instance, distance
bounding protocols explicitly admit failures.
While the most effective methods of the types mentioned in point 1 require
asymmetric cryptography (see, e.g., [590]), there are possibilities to create narrow
covert channels even if a random string is processed with, say, a hash function.
Assume for instance that the device chooses r at random, while Hash(r) is available
to the adversary. Assume that a malicious device executing the protocol intends to
leak bits of a string μ of length 2 l . Assume also that it has a secret key k shared
with the adversary, who is observing the communication channel. Instead of just
choosing r at random, computing Hash(r), and presenting it, the following steps are
executed:
1. choose r at random, s := Hash(r), z := Hash(s, k),
2. parse z as a||b|| . . ., where a consists of l bits and b consists of m bits,
3. goto 1, if the m-bit substring of μ starting at position a is different from b,
4. output s.
Of course, this is a narrow channel, as m must be small enough so that an
appropriate r can be found in a reasonable time—in practice we are talking about
a few bits per protocol execution. Note that this procedure works for any hash
function. It works also if the loop may be executed only a limited number of times
and, during the last loop execution, steps 2 and 3 are omitted. Unfortunately, if a
device is delivered as a black-box, then the possibilities to inspect what the device
is doing are severely limited. There are only a few exceptions (see, e.g., [94]).
1.2.2 Active Watchdog Concept
The general idea is that a device is controlled by its dedicated watchdog coming
from a source independent from the device manufacturer and the device provider.
The watchdog should detect malicious operation or make it ineffective, given that
no access to the internal operation of the device controlled is granted. A watchdog
is an active device, modeled as follows:
• it controls the whole communication between the device and the external world,
• it can delete and change all messages,
• it may challenge the device during extra interactions executed by them.
The idea of separating the tasks between two independent devices is an old
concept [136]. The same concerns supervising computation correctness by an
external unit [97]. Nevertheless, it has attracted more attention in the post-Snowden
era, being used, among others, in a solution guarding against subversion attacks on
cryptographic devices—see the paper [31] and an extension [510].
